case $hoster {
"ubcece", "darmstadt", "ftcollins", "grnet": { include resolv }
}
+ case $hostname {
+ brahms: { include ferm }
+ }
}
path => "/etc/init.d:/usr/bin:/usr/sbin:/bin:/sbin",
refreshonly => true,
}
+ ferm::rule { "dsa-munin":
+ description => "Allow munin-node from spohr.debian.org",
+ rule => "proto tcp dport 4949 saddr $HOST_MUNIN ACCEPT"
+ prio => "02"
+ }
}
package {
nagios-nrpe-server: ensure => installed;
}
+ ferm::rule { "dsa-nagios":
+ description => "Allow nrpe from spohr.debian.org",
+ rule => "proto tcp dport 5666 saddr $HOST_NAGIOS ACCEPT"
+ prio => "03"
+ }
}
path => "/etc/init.d:/usr/bin:/usr/sbin:/bin:/sbin",
refreshonly => true,
}
+ ferm::rule { "dsa-ssh":
+ description => "Allow SSH",
+ rule => "proto tcp dport ssh ACCEPT",
+ domain => "(ip ip6)",
+ prio => "01"
+ }
+
}